CVE-2017-9287
Summary
| CVE | CVE-2017-9287 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-29 16:29:00 UTC |
| Updated | 2022-06-13 19:18:00 UTC |
| Description | servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| OpenLDAP 'servers/slapd/back-mdb/search.c' Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| OpenLDAP ITS - Message 8655 |
CONFIRM |
www.openldap.org |
Exploit, Patch, Vendor Advisory |
| Security Bulletin - Policy Auditor update fixes multiple vulnerabilities in third-party libraries (CVE-2016-0718, CVE-2016-4472, CVE-2016-5300, CVE-2017-17740, CVE-2017-9287, CVE-2019-13057, CVE-2020-15719, CVE-2019-1543, CVE-2019-1547, CVE-2019-1552, CVE-2019-1563, CVE-2019-8457, CVE-2018-20506, CVE-2018-20346, CVE-2019-16168, CVE-2017-12627) |
CONFIRM |
kc.mcafee.com |
|
| #863563 - openldap: CVE-2017-9287: double free with Paged Results control and pagesize 0 - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
Issue Tracking, Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-3868-1 openldap |
DEBIAN |
www.debian.org |
|
| OpenLDAP Double Free Memory Error Lets Remote Authenticated Users Cause the Target slapd Service to Crash - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500476 Alpine Linux Security Update for openldap
- 504234 Alpine Linux Security Update for openldap